nerdexam
Microsoft

MS-900 · Question #372

Hotspot Question A company uses the Microsoft Intune Connector for Active Directory in Microsoft Endpoint Manager. Instructions: For each of the following statements, select Yes if the statement is…

This hotspot question tests knowledge of the Microsoft Intune Connector for Active Directory, specifically its requirements, capabilities, and limitations when used with Microsoft Endpoint Manager for hybrid Azure AD join scenarios.

Submitted by joshua94· Mar 5, 2026Describe Microsoft 365 apps and services

Question

Hotspot Question A company uses the Microsoft Intune Connector for Active Directory in Microsoft Endpoint Manager. Instructions: For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point. Answer:

Exhibit

MS-900 question #372 exhibit

Answer Area

  • The connector adds entries to on-premises Active Directory domains for computers that enroll by using Windows Autopilot.
  • The connector allows device access to Microsoft Exchange servers if devices are compliant with preset Intune policies.
  • The connector processes certificate requests from devices that use certificates for authentication.

Explanation

This hotspot question tests knowledge of the Microsoft Intune Connector for Active Directory, specifically its requirements, capabilities, and limitations when used with Microsoft Endpoint Manager for hybrid Azure AD join scenarios.

Approach. The Microsoft Intune Connector for Active Directory enables Autopilot hybrid Azure AD join by allowing Intune to create computer accounts in on-premises AD. Key facts: (1) The connector must be installed on a domain-joined Windows Server that has line-of-sight to the domain controller. (2) Multiple connectors can be installed for load balancing and redundancy. (3) The connector requires the installing account to have permissions to create computer objects in the target OU. (4) The connector communicates outbound to Intune service (no inbound firewall rules needed). (5) A single connector can support creating up to approximately 300 Autopilot enrollments per week. Evaluating each statement against these established facts and Microsoft documentation will yield the correct Yes/No determination for each row.

Concept tested. Microsoft Intune Connector for Active Directory - its installation requirements, supported scenarios (hybrid Azure AD join via Windows Autopilot), network/firewall prerequisites, scalability (multiple connectors), and permission requirements for computer object creation in on-premises Active Directory.

Reference. https://learn.microsoft.com/en-us/mem/intune/enrollment/windows-autopilot-hybrid#install-the-intune-connector-for-active-directory

Topics

#Microsoft Intune Connector#Windows Autopilot#device compliance#certificate authentication

Community Discussion

No community discussion yet for this question.

Full MS-900 Practice